Tracking Security and IT Initiatives with Goals
The runZero Goals feature turns any inventory query into a measurable objective, so you can track, measure, and report on the progress of an initiative over time, whether it aims to improve your security posture, meet compliance obligations, or maintain IT hygiene.
Who is this playbook for and why?
This playbook is for IT, Security, and Compliance teams who need to:
- Measure progress against specific objectives, such as eliminating end-of-life software or giving every asset an owner.
- Create trackable Key Performance Indicators (KPIs) from their asset inventory data.
- Report on the status of security and IT initiatives to management and stakeholders.
How will runZero help?
A Goal gives you a clear, visual way to track progress against any objective you can define with an inventory query. runZero compares the current number of assets matching the query with the target you set, so you can see how each initiative is progressing and where it needs more attention.
What will I need to do?
To track an initiative with runZero Goals, you will:
- Define a clear objective for your organization.
- Create a runZero query that identifies all assets related to that objective.
- Create a Goal to track the query results against a specific target.
- Monitor the Goal to view progress and report on your success.
Prerequisites
- A complete asset inventory. The more complete your inventory data, the more accurate your Goals.
Steps to implement
These steps create and track a new Goal. The example is a Goal to eliminate all end-of-life operating systems.
1. Define your objective and query
Decide what you want to achieve and how to find the relevant assets in your inventory.
- Objective: Eliminate all assets running an end-of-life (EoL) operating system.
- Query: Find these assets with the runZero query language. You can build and test the query in the Asset Inventory. For this example, the query is:
(os_eol_extended:>0 AND os_eol_extended:<now) OR (os_eol_extended:0 AND os_eol:<now)
2. Create the Goal
With the query ready, create the Goal.
- Go to Goals.
- Click New goal.
- Click Create baseline goal.
- Fill in the Goal details:
- In Name, give the goal a clear, descriptive name, for example
Eliminate End-of-Life Operating Systems. - In Description, explain the purpose of the goal, for example
Track the number of assets running unsupported OS versions to reduce security risk and maintain compliance. - In Target query, paste the query from the previous step, for example
(os_eol_extended:>0 AND os_eol_extended:<now) OR (os_eol_extended:0 AND os_eol:<now). - In Baseline query, define the assets in scope for this goal. This example scopes the goal to assets with an EoL value set, so the baseline is
has_os_eol:t. - Under Set the goal threshold, define what counts as success, as either a percentage or a count of assets. If you want 0 assets past EoL, use
Less than or equal to; 0; Fixed number. To allow a buffer, use a percentage such asLess than or equal to; 5; Percent.
- In Name, give the goal a clear, descriptive name, for example
- Click Save.
3. Monitor and report
After you create a Goal, pin it to the dashboard to monitor its progress. The dashboard shows the current status against your target at a glance, so you can track your team’s progress and report on the success of your initiatives. Tracking goal progress covers creating and monitoring goals in more detail.
Sample Goals
These Goals track other common security and IT initiatives. You will likely need to make slight adjustments to the target and baseline queries to match what is in scope in your environment.
Goal: Close gaps in vulnerability scan coverage
- Description: Tracks assets runZero has discovered that your vulnerability scanner has not seen, so you can close gaps in your vulnerability management program.
- Target Query:
source:runZero AND not source:tenable(replacetenablewith your vulnerability management source, such asqualysorrapid7). - Baseline Query:
type:server OR type:desktop OR type:laptop - Goal Threshold:
Less than or equal to 5%
Goal: Update logins on all services using default passwords
- Description: Tracks services that use a default credential for login.
- Target Query:
finding_name:"Service Accessible With Default Credentials" - Baseline Query:
alive:t - Goal Threshold:
Less than or equal to 0
Goal: Remediate publicly exposed RDP
- Description: Tracks assets with the Remote Desktop Protocol (RDP) exposed to the public internet, a significant security risk.
- Target Query:
service_has_public:t and protocol:rdp - Baseline Query:
has_public:t - Goal Threshold:
Less than or equal to 0
Goal: Assign ownership to all assets
- Description: Tracks assets with no owner assigned in runZero, to enforce IT hygiene.
- Target Query:
has_owner:f - Baseline Query:
alive:t - Goal Threshold:
Less than or equal to 25%
Outcome demo
This short video demos what creating and tracking Goals may look like.
Getting help
For help with the Goals feature, book a session with a runZero Customer Success Engineer.